CVE-2026-22678

Source
https://cve.org/CVERecord?id=CVE-2026-22678
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22678.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22678
Published
2026-05-21T20:59:52Z
Modified
2026-08-12T03:51:31Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Webmin < 2.641 Stored XSS via System and Server Status
Details

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in save_tmpl.cgi and rendered unescaped in list_tmpls.cgi.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22678.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "2.641"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "2.641"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "2.641"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/webmin/webmin

Affected ranges

Type
GIT
Repo
https://github.com/webmin/webmin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.641"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

1.*
1.700
1.710
1.720
1.730
1.740
1.750
1.760
1.770
1.780
1.790
1.800
1.801
1.810
1.820
1.830
1.831
1.840
1.850
1.860
1.870
1.880
1.890
1.900
1.910
1.920
1.930
1.940
1.941
1.950
1.951
1.953
1.954
1.955
1.960
1.962
1.970
1.972
1.973
1.974
1.980
1.982
1.983
1.984
1.990
1.991
1.993
1.994
1.995
1.996
1.998
1.999
2.*
2.000
2.001
2.003
2.010
2.011
2.012
2.013
2.020
2.021
2.100
2.103
2.104
2.105
2.110
2.111
2.200
2.201
2.202
2.301
2.302
2.400
2.401
2.402
2.501
2.510
2.520
2.600
2.610
2.620
2.621
2.630
2.640

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22678.json"